As far as I know, Magic Quotes uses the built-in addslashes() function to escape characters, and is reliant on Unicode. This means it could be vulnerable to certain types of character encoding. A quick Wikipedia search confirms this. Third point under Criticism.

good idea. I read up a bit but I couldn't actually get the unicode to translate to it's char. It would come out as the literal U+0027 or N0027. Do you have any tips on out to get it to parse the unicode or how to inject unicode SQL?